PT-2026-50740 · Zitadel · Zitadel

CVE-2026-55671

·

Published

2026-06-18

·

Updated

2026-07-30

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Zitadel versions 4.0.0 through 4.15.1 Zitadel versions 3.0.0 through 3.4.11
Description A Server-Side Request Forgery (SSRF) issue exists in components that handle outgoing HTTP requests, specifically HTTP Notification Channels, OIDC BackChannel Logout, and SAML Metadata URL Fetches. User-defined URLs were not properly validated against an internal denylist, allowing attackers to provide arbitrary URLs such as loopback addresses, internal IPs, or cloud link-local addresses. This could enable internal network mapping, port scanning, or interaction with unauthorized internal services. The denylist mechanism was also susceptible to DNS rebinding (a technique to bypass DNS-level security checks by changing the IP address associated with a domain name between the time of validation and the time of use), HTTP redirects, and protocol downgrades from HTTPS to HTTP. In cloud environments, this could potentially be used to target unauthenticated cloud metadata endpoints like 169.254.169.254.
Recommendations Upgrade Zitadel versions 4.0.0 through 4.15.1 to version 4.15.2 or later. Upgrade Zitadel versions 3.0.0 through 3.4.11 to version 4.15.2 or later. Implement strict network policies, egress firewalls, or reverse proxy rules to block outbound connections from Zitadel to internal networks, loopback interfaces, or cloud metadata endpoints.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55671
GHSA-29JH-8CFQ-RR8X
GO-2026-5059
OPENSUSE-SU-2026:21483-1

Affected Products

Zitadel